CSRF Vulnerability in Roskus Prospero Flow CRM
CVE-2026-82911

5.1MEDIUM

Key Information:

Vendor

Roskus

Vendor
CVE Published:
4 September 2026

What is CVE-2026-82911?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the OrderConfirmController of Roskus Prospero Flow CRM versions prior to 5.15.11. This vulnerability allows an unauthenticated attacker to confirm any pending order on behalf of a legitimate user by directing them to a specially crafted webpage. The issue arises because CSRF tokens are enforced only on HTTP methods that alter data (POST, PUT, PATCH, DELETE), leaving the GET request for order confirmation unprotected. As a result, attackers can leverage sequential order numbers to automate the confirmation of multiple orders in a single attack, bypassing user authorization completely.

Affected Version(s)

Prospero Flow CRM 0 < 5.15.11

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DarĂ­o ChacĂłn
Mario Álvarez
DarĂ­o Rivas Quero
Cristian FernĂĄndez Cornejo
Secur0 CNA
Gustavo Novaro
.